‘GitLost’: researchers tricked GitHub’s AI agent into leaking private repos
The Next Web
Read full postSecurity researchers at Noma Labs discovered a vulnerability called GitLost in GitHub's AI Agentic Workflows that allows private repository contents to be leaked publicly via a simple issue with crafted prompts. The flaw exploits prompt injection, bypassing GitHub's guardrails, and currently has no code fix or official documentation from GitHub.




